Attacker exploited StakeDAO mint function to create 5.4 trillion vsdCRV tokens and swap to ETH.
Security & Exploits ·
An attacker exploited a vulnerability in StakeDAO's mint function to generate approximately 5.4 trillion vsdCRV tokens. The exploit was executed on the Arbitrum network, with the attacker's address subsequently conducting swaps to convert the minted tokens into ETH.
The attack leveraged a flaw in the protocol's token minting mechanism, allowing the creation of an extraordinarily large supply of vsdCRV that vastly exceeded legitimate circulation. The attacker then moved to liquidate these tokens through swap operations, likely exerting downward pressure on the token's market value.
It remains unclear what immediate remediation steps StakeDAO has taken, whether the exploit has been fully halted, or what the total financial impact to protocol participants and liquidity providers amounts to. The full scope of tokens successfully converted to ETH and potential recovery mechanisms have not yet been detailed.